Manager - CCDI (Centre for Cyber Defence & Intelligence)

The Financial Conduct AuthorityLondon, Leeds, EnglandOn-siteFull-timeStaff, 8–12 yearsListed 3 hours ago

Apply now

About this role

Job title: Manager - CCDI (Centre for Cyber Defence & Intelligence)

Division: Operations 
Department: Cyber & Information Resilience (C&IR)

- Salary: National (Edinburgh and Leeds) ranging from £74,900 to 115,000 and London from £82,300 to £125,000 (salary offered will be based on skills and experience)
- This role is graded as: Manager, Regulatory
- Your external recruitment contact is Raimonda Stankute via [email protected] (mailto:[email protected])
- Your internal recruitment contact is Lauren McHale via [email protected] (mailto:[email protected])
- Applications must be submitted through our online portal. Applications sent via social media or email will not be accepted.

About the FCA and team

We regulate financial services firms in the UK, to keep financial markets fair, thriving and effective. By joining us, you’ll play a key part in protecting consumers, driving economic growth and shaping the future of UK finance services.

We are recruiting a Manager to lead the FCA's Threat, Detection & Response function, the Centre for Cyber Defence and Intelligence, part of Cyber & Information Resilience (C&IR) at the FCA. This is an exciting time to join the function as the FCA increases its adoption of AI and agent-based technologies. These developments create opportunities to modernise cyber defence, while also requiring a significant uplift in security monitoring, telemetry, detection engineering and response capabilities to manage new and evolving risks.

The FCA regulates over 35,000 financial services firms in the UK, setting standards for firms to meet and holding them to account if they do not. We enable a fair and thriving financial services market for the good of consumers and the UK economy. The CCDI Manager will operate and mature an intelligence-led cyber defence capability, translating current threat intelligence into monitoring priorities, detection improvements, exposure insight and measurable improvement in incident response. The role links Threat Intelligence, Security Operations, Detection Engineering, Cyber Assurance and Technology teams, including outsourced partners and maintains a data-driven view of detection effectiveness, response performance, service outcomes and coverage gaps.

Role responsibilities

- Lead and develop the FCA's Threat Intelligence, Detection and Incident Response capability, delivering an intelligence-led approach to cyber defence and risk reduction
- Drive continuous improvement of detection coverage, telemetry, response effectiveness and security operations through data-led insights, automation and effective stakeholder engagement.
- Shape the security monitoring response to increased adoption of AI and agent-based technologies, ensuring that telemetry, detection logic and response capabilities evolve alongside the FCA’s technology environment.
- Own the detection improvement roadmap, working closely with SOC providers, technology teams and cyber security stakeholders to deliver measurable outcomes
- Lead and develop internal teams and third-party partners, ensuring effective performance, service quality and continuous professional growth
- Establish meaningful cyber security metrics, KPIs and executive reporting to measure performance, resilience and risk reduction
- Build trusted relationships across the FCA and external cyber security communities to improve threat awareness, influence priorities and share best practice
- Ensure alignment with industry frameworks and guidance, including NIST CSF, MITRE ATT&CK, MITRE D3FEND, INFORM and NCSC standards

Skills required

Minimum:

- Experience leading Cyber Security, Security Operations, Threat Intelligence or Detection Engineering teams, including developing people and delivering results through others
- Solid knowledge of modern cyber threats, detection, threat intelligence and incident response, with experience managing cyber security partners and service providers
- Effective stakeholder management and communication skills, with the ability to translate complex technical risks, security metrics and data into clear executive insights and recommendations
- Advanced analytical and problem-solving skills, using data-driven approaches to improve security outcomes, operational effectiveness and cyber resilience

Essential:

- Experience in one or more of Threat Intelligence, Security Operations, Detection Engineering, SOC Performance Management or Exposure Management, with a practical understanding of threat-informed defence methodologies, security monitoring, incident response and frameworks such as MITRE ATT&CK for adversary behaviour, D3FEND for defensive countermeasures, and INFORM for measuring defensive maturity.
- Experience using security performance metrics, KPIs, KRIs, cyber maturity measures and operational reporting to support informed decision-making, continuous improvement and measurable cyber risk reduction
- Experience delivering improvements to detection coverage, signal quality, response effectiveness and cyber resilience, including the use of automation, SOAR, telemetry enrichment, attack simulation or purple teaming approaches
- Solid knowledge of cyber security controls across cloud, SaaS and enterprise environments, with experience using technologies such as Microsoft Defender, Microsoft Sentinel, CrowdStrike, AWS Security Services or similar security platforms
- Demonstrated ability to influence senior stakeholders, communicate complex technical concepts to a range of audiences and produce high-quality governance papers and executive reporting
- Knowledge of operational resilience, cloud security and regulatory expectations within complex or highly regulated environments
- Relevant cyber security certifications such as CISSP, CISM, GIAC, SANS, Azure Security, AWS Security or equivalent are advantageous

Benefits

- 28 days annual leave plus bank holidays
- Non-contributory pension (8–12% depending on age) and life assurance at eight times your salary
- Private healthcare with Bupa, income protection and 24/7 Employee Assistance
- 35 hours of paid volunteering annually
- Colleagues spend a minimum of 50% of their working time in the office each month (60% for Directors and Executive Directors) across our London, Leeds and Edinburgh offices. A flexible benefits scheme designed around your lifestyle

For a full list of our benefits and our recruitment process as a whole visit our benefits page .

Our values and culture

Our colleagues are the key to our success as a regulator. We are committed to fostering a diverse and inclusive culture: one that’s free from discrimination and bias, celebrates difference and supports colleagues to deliver at their best. We believe that our differences and similarities enable us to be a better organisation – one that makes better decisions, drives innovation and delivers better regulation.

If you require any adjustments due to a disability or condition, your recruiter is here to help - reach out for tailored support.

We welcome diverse working styles and aim to find flexible solutions that suit both the role and individual needs, including options like part-time and job sharing where applicable.

Disability confident: our hiring approach

We’re proud to be a Disability Confident Employer and therefore, people or individuals with disabilities and long-term conditions who best meet the minimum criteria for a role will go through to the next stage of the recruitment process. In cases of high application volumes we may progress applicants whose experience most closely matches the role’s key requirements.

Useful information and timelines

Timeline:

- Job advert closes: Midnight, 20th October 2026
- CV Review/Shortlist: 22nd October 2026
- First stage interviews: w/c 26th October 2026
- Assessments: w/c 2nd November 2026
- Second stage interviews: w/c 16th November 2026
- Your Recruiter will discuss the process in detail with you during screening for the role, therefore, please make them aware if you are going to be unavailable for any date during this time.
- SC Clearance is required for this role (SC Guidance (https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.gov.uk%2Fgovernment%2Fpublications%2Funited-kingdom-security-vetting-clearance-levels%2Fsc-guidance-pack-for-applicants&data=05%7C02%7CDemi.Scarsella%40fca.org.uk%7C9f3b6e9f0bd2403b467908dcaafda135%7C551f9db3821c44578551b43423dce661%7C1%7C0%7C638573253515600021%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=O4icJrVVef0RCaJA0LmORwcMSk3OpWU%2Bi74JVXscLlc%3D&reserved=0)) - you will hold or will be required to obtain Security Check (SC) level vetting